

I really don’t think it is.


I really don’t think it is.


An unfortunate turn. 1Password has been at the front of the pack in password managers for a long time. There are other options, but 1Password has stood out for features and because “it just works.”
Now I suppose I’ll have to find an alternative. I like Bitwarden’s openness but it isn’t nearly as polished. Maybe this is an opportunity for them or others to rise to the front.


This was the goal all along. If the mail isn’t trustworthy, then there’s no reason to keep it around as a service. So we can get rid of it by transferring it to the highest briber bidder.


Charlie Sheen, Ben Vereen, Shrink to the size of a Lima bean!


Authentication & single sign-on service
Plugged into Reverse proxy, routing to each service by name
With a wild card cert so there are no name leaks.
Make your urls unexpected. If your domain is example.com, don’t put your jellyfin server at jellyfin.example.com. Instead, use watch.example.com or telly.example.com. Anything that’s memorable to you about what the service is without using a specific brand name.
With a wildcard dns record to point all names to your IP, and a wildcard certificate that works for all names loaded on your load balancer, it becomes hard for a hacker to know what name to use to get the load balancer to send them to the service they want to hack.
If you then use a sso tool like traefik’s ForwardAuth middleware, you won’t even get to the service until you’ve first authenticated.
Separate admin accounts is a good idea. It can be overdone. For example, you might decide you need one account for proxmox admin, one for network devices, a third for your IAM stack and a fourth for apps. I personally think that’s too much.
Every human admin needs a separate admin account. If you’re using AI, each agent needs its own privileged access too.
I recommend having as few privileged accounts as is reasonable. It might make sense to separate network admin from the rest, for example, or some other separation. But it might be fine in your case to have one master-admin account.
Getting the mapping right is the hard part. Most IdP-aware apps have some way to map roles, groups, or whatever privilege management they use.